Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: XENOTIME
0
techniques
2
software
0
corpus matches
profile
TEMP.Veles is a Russia-based threat group that has targeted critical infrastructure. The group has been observed utilizing TRITON, a malware framework designed to manipulate industrial safety systems.
software
2 malware & tools attributed
Mimikatz
S0002
PsExec
S0029
read this carefully
0 corpus matches is not attribution
That count is indicators which exhibit techniques TEMP.Veles is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.